ManageEngine ADManager version 7183 suffers from a password hash disclosure vulnerability.
ddade0c8d44290aca9a54f0c1621504614026325fdfa745fc4d9c008c6feca03
Debian Linux Security Advisory 5781-1 - Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
1ef039858c6f77289a0121b0f10830b4ab7779904de169e39eb4e8d6420d6fe6
Microsoft Office 2019 MSO build 1808 (16.0.10411.20011) and Microsoft 365 MSO version 2403 build 16.0.17425.20176 suffer from an NTLMv2 hash disclosure vulnerability.
a515b741cb4fdee423e7ca948fc50654803bd1c926175eccc8866a749034e338
Supply Chain Management version 1.0 suffers from a backup disclosure vulnerability.
ede00ad1b8f81b125e0be45a893d89d85ad8a477424a3733200965b882b35e48
Debian Linux Security Advisory 5775-1 - Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
4ef90a203d4a92a51da2468a0cde68b6e452ea76592676b5c73bc801e84ae24f
Aquatronica Control System version 5.1.6 suffers from a hash disclosure vulnerability.
f97e8496dea3f74570e81811208c8ab73c042ae1f3e28024e2d731482de127db
Multi Branch School Management System version 3.5 suffers from a backup disclosure vulnerability.
b4c3fb3408f8d7a80baf2b5ec0b035520c60a8b287134c61abe01863834639ea
Complete Multi Hospital Management System version 1.0 suffers from a backup disclosure vulnerability.
e760cf3c5b44d7d8984817fcf92204fd9912a026b5d02720406cc72f12ac70ed
Reservation Management System version 1.0 suffers from a backup disclosure vulnerability.
3fdb31b63dd3dffcc359c8fe22cdbfc2692c268e17a6a1cc41302fd995ff1353
Gentoo Linux Security Advisory 202409-20 - Multiple vulnerabilities have been discovered in curl, the worst of which could lead to information disclosure. Versions greater than or equal to 8.7.1 are affected.
f394b76c205156192ead8c0293e0772f5056819abf8ec95aff9c332a2bf86573
Gentoo Linux Security Advisory 202409-14 - Multiple vulnerabilities have been discovered in Mbed TLS, the worst of which could lead to information disclosure or denial of service. Versions greater than or equal to 2.28.7 are affected.
c39110a508d640140269a45e62b4d73c71bf5d63d281f69666dd0e64f45aa664
Gentoo Linux Security Advisory 202409-8 - Multiple vulnerabilities have been discovered in OpenVPN, the worst of which could lead to information disclosure. Versions greater than or equal to 2.6.7 are affected.
845e07a967854ba9249cd7ad779d329d4ab74df98fb814e200427249cb1a5191
Debian Linux Security Advisory 5773-1 - Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
8898d709ae27812683b98775f6cd9542d1faa76d04a8943e6f4624dc1dd38dd4
Proof of concept exploit that demonstrates an information disclosure vulnerability in Check Point Security Gateways.
3d1d9908347cad7b090b35327c160e791c08878516956e5f60997b2cd3d13687
Online Exam System version 1.0 suffers from an information disclosure vulnerability.
3fbc8bcc74c7317d3bf390f23c3b7550d02c847fadb5dafb1fbf9a36b88079c8
Debian Linux Security Advisory 5768-1 - Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
70403858627e4d47b4cd0877efdac30fb9f6d23926c76535c39787794a947584
Debian Linux Security Advisory 5766-1 - Security issues were discovered in Chromium which could result in the execution of arbitrary code, denial of service, or information disclosure.
2df8f77a82336c5f2385c3125fe0ac80b9f8996b478a80263fdb30393436cc59
Texas Instruments Fusion Digital Power Designer version 7.10.1 allows a local attacker to obtain sensitive information via the plaintext storage of credentials.
7d2282798e3247a2123a5993d7d6d2cb77a3755e9e0270c916b57856fbfaf0ef
This Metasploit module exploits an information disclosure vulnerability in WordPress Plugin "WP Mobile Pack" version 2.1.2, allowing to read files with privileges information.
6091faba1f9f0346060b398514c9a02c65d456b6313c9ebd4ae6e2025f13b2e5
The Wordpress plugin BulletProof Security, versions less than or equal to 5.1, suffers from an information disclosure vulnerability, in that the db_backup_log.txt is publicly accessible. If the backup functionality is being utilized, this file will disclose where the backup files can be downloaded. After downloading the backup file, it will be parsed to grab all user credentials.
67c4807293a251cc053fbb1a5fb7a2329f603f6abac1003faf1823ea7751fe74
This Metasploit module can detect situations where there may be information disclosure vulnerabilities that occur when a Git repository is made available over HTTP.
f3fc66ff62ad13f3081bddfba7d9e771214b26ddbd974bf809d56a802a53e08c
This Metasploit module exploits an information disclosure vulnerability that allows an unauthenticated user to enumerate users in the /ViewUserHover.jspa endpoint. This only affects Jira versions < 7.13.16, 8.0.0 ≤ version < 8.5.7, 8.6.0 ≤ version < 8.11.1 Discovered by Mikhail Klyuchnikov @__mn1__ This Metasploit module has been tested on versions 8.4.1, 8.5.6, 8.10.1, 8.11.0.
9986ec180d087e713848f6f47f32573f8332f188e2e0668566a302808f278b36
This Metasploit module exploits an information disclosure vulnerability in the Views module of Drupal, brute-forcing the first 10 usernames from a to z. Drupal 6 with Views module less than or equal to 6.x-2.11 are vulnerable. Drupal does not consider disclosure of usernames as a weakness.
03ba69cb09e97d79a5017073561678cbbb9c205b5d53faacede76e154667dd3a
Uses information disclosure to determine if MS17-010 has been patched or not. Specifically, it connects to the IPC$ tree and attempts a transaction on FID 0. If the status returned is "STATUS_INSUFF_SERVER_RESOURCES", the machine does not have the MS17-010 patch. If the machine is missing the MS17-010 patch, the module will check for an existing DoublePulsar (ring 0 shellcode/malware) infection. This Metasploit module does not require valid SMB credentials in default server configurations. It can log on as the user "\" and connect to IPC$.
7da47a7e8285d0a6b8ee0d6e5384264f78b38a3863420fbdc47ecf044ace7dde
The Moxa protocol listens on 4800/UDP and will respond to broadcast or direct traffic. The service is known to be used on Moxa devices in the NPort, OnCell, and MGate product lines. A discovery packet compels a Moxa device to respond to the sender with some basic device information that is needed for more advanced functions. The discovery data is 8 bytes in length and is the most basic example of the Moxa protocol. It may be sent out as a broadcast (destination 255.255.255.255) or to an individual device. Devices that respond to this query may be vulnerable to serious information disclosure vulnerabilities, such as CVE-2016-9361. The module is the work of Patrick DeSantis of Cisco Talos and is derived from original work by K. Reid Wightman. Tested and validated on a Moxa NPort 6250 with firmware versions 1.13 and 1.15.
98b6bc9ac986f9cabba0156932ffefd60159a96b8107e1d9b3448bedd300ff36